hackers send RemcosRAT malware emails

Criminals continue to use the problems of mass concern of Ukrainians to spread malicious software. Specialists of CERT-UA recorded a mass distribution of e-mails speculating on the subject of “Kyivstar” and the SBU.

Yes, letters about “Debt under the Kyivstar contract” will begin to be sent to the e-mail boxes of Ukrainians. They have an attachment in the form of the “Subscriber’s Debt.zip” archive, which contains a password-protected archive of the same name. In the latter, there is a document with the macro “Subscriber Debt.doc”. When activated, the macro code will download and run the GB.exe file. This is an SFX archive containing a BATCH script to download and run the wsuscr.exe executable to run the RemcosRAT remote control program.

At the same time, CERT-UA recorded the distribution of letters with the subject “SBU request” and an attachment in the form of a “Documents.zip” archive. It contains a password-protected RAR archive “Zapyt.rar” with an executable file “Zapyt.exe”. Opening the archive and running the file leads to the infection of the system with the remote access program RemcosRAT.

CERT-UA experts note that in addition to the typical UAC-0050 placement of the RemcosRAT control servers at the technical site of the Malaysian hosting provider Shinjiru, they are also located within the autonomous system AS44477.

CERT-UA specialists recommend filtering e-mails with password-protected attachments (both archives and documents) at the level of mail gateways.

Related Posts

UK to regulate cryptocurrency memes: illegal advertising

Britain’s financial services regulator has issued guidance to financial services companies and social media influencers who create memes about cryptocurrencies and other investments to regulate them amid…

unofficial renders of the Google Pixel 9 and information about the Pixel 9 Pro XL

The whistleblower @OnLeaks and the site 91mobiles presented the renders of the Google Pixel 9 phone. Four images and a 360° video show a black smartphone with…

Embracer to sell Gearbox (Borderlands) to Take-Two (Rockstar and 2K) for $460 million

Embracer continues to sell off assets – the Swedish gaming holding has just confirmed the sale of The Gearbox Entertainment studio to Take-Two Interactive. The sum is…

photo of the new Xbox X console

The eXputer site managed to get a photo of a new modification of the Microsoft Xbox game console. The source reports that it is a white Xbox…

Israel Deploys Massive Facial Recognition Program in Gaza, – The New York Times

The Technology section is powered by Favbet Tech The images are matched against a database of Palestinians with ties to Hamas. According to The New York Times,…

Twitch has banned chest and buttock broadcasts of gameplay

Twitch has updated its community rules and banned the focus of streams on breasts and buttocks. According to the update, starting March 29, “content that focuses on…

Leave a Reply

Your email address will not be published. Required fields are marked *